Vulnerable Systems:
*Oracle Outside In 8.3.7
*Oracle Outside In 8.3.5.0
Oracle Outside In is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
The 'Outside In Image Export SDK' sub component is affected.
Vendor Status:
Orcale had since issued an update for this vulnerability.
Disclosure Timeline:
2012-January-23 Rev 3. Updated JD Edwards information for One World Tools SP24
2012-January-18 Rev 2. Updated credit information
2012-January-17 Rev 1. Initial Release